2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-7433——NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified...
CVE-2016-7431——NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp o...
CVE-2016-7429——NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remo...
CVE-2016-7428——ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the ...
CVE-2016-7427——The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a deni...
CVE-2016-7426HIGH7.5NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is...
CVE-2016-6887——The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might a...
CVE-2016-6886——The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory...
CVE-2016-6885——The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free a...
CVE-2016-2090CRITICAL9.8Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via ...
CVE-2016-9882HIGH7.5An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to...
CVE-2016-3130——An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 thro...
CVE-2016-3128——A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to ...
CVE-2016-10141CRITICAL9.8An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before...
CVE-2016-10140——Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled wi...
CVE-2016-10139——An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The two package names involved in the exfiltr...
CVE-2016-10138——An issue was discovered on BLU Advance 5.0 and BLU R1 HD devices with Shanghai Adups software. The com.adups.fota.sysope...
CVE-2016-10137——An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sys...
CVE-2016-10136——An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sys...
CVE-2016-10135——An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA ...
CVE-2016-9299——The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a...
CVE-2016-6492——The MT6573FDVT_SetRegHW function in camera_fdvt.c in the MediaTek driver for Linux allows local users to gain privileges...
CVE-2016-5737——The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-gerrit) improperly marks text/html as a s...
CVE-2016-5715——Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attacker...
CVE-2016-3152——Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downl...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now